Three different versions of firmware update available

Hi everyone,
I have Ubuntu 24.04 LTS default selection installed in a Lenovo V15 G4 IRU notebook, double boot with Windows.

Minutes ago I received three notifications:

  • Firmware update available for UEFI dbx: UEFI dbx can be upgraded from version 20250507 to 20250902
  • Firmware update available for UEFI CA: UEFI CA can be upgraded from version 2011 to 2023
  • Firmware update available for KEK CA: KEK CA can be upgraded from version 2011 to 2023

Am I expected to do all the three upgrades? Is it safe?

Thanks in advance

Those aren’t different versions, they are distinct updates for specific components relating to Secure Boot.

Am I expected to do all the three upgrades? Is it safe?

Yes, fwupdmgr, the service doing the update, is pretty safe to use. But it’s a firmware update, so a certain level of calculated risk is involved; it’s up to you to decide, if you ultimately trust it to not fall on its face.

See this for more info on the firmware updates in general:
https://lvfs.readthedocs.io/en/latest/intro.html
(fwupdmgr is the reference implementation to provide those updates, authored by a Red Hat developer — so not just some hobbyist; if it’s good enough for RHEL, it’s probably good enough for us.)

and this on the topic of those specific updates:

4 Likes

I did the first update and restarted Ubuntu as requested: how can I do now the other two? Do I have to wait for the notifications to reappear?

Those should all be installed already. It’s usually a package deal, so fwupdmgr writes them all out, and if a reboot is required you just follow suit and then it’s done. Unless one update pre-depends another, but that’s not the case here, IIRC. Those updates happened for me a while ago already; but some issues prevented them to be rolled out to some people.

1 Like

You can check in the terminal. Run the following three commands in a terminal:

fwupdmgr refresh
fwupdmgr get-updates
fwupdmgr update

If there are outstanding updates, it will prompt you to install and reboot.

1 Like

Today I received two notifications for the two remaining updates: UEFI CA and KEK CA, so it seems that the three updates should be done separately.

I did successfully the UEFI CA update and now I am waiting for the KEK CA update notification

I tried the fwupdmgr get-updates command and it looks a bit complicated. It requires a Review and upload report to the hardware vendors, if I understood correctly. I did not proceed with the upload because the verbosity of the output scared me (!)

$ fwupdmgr get-updates
Devices with no available firmware updates:
• 06FA:00 04F3:32B9
• BIOS1
• ESSENCORE NVME GEN3 SSD
• KEK CA
• Option ROM UEFI CA
• System Firmware
• UEFI Device Firmware
• UEFI Device Firmware
• UEFI Device Firmware
• UEFI Device Firmware
• UEFI Device Firmware
• UEFI Device Firmware
• UEFI Device Firmware
• Windows Production PCA
Devices with the latest available firmware version:
• UEFI CA
• UEFI dbx
────────────────────────────────────────────────
Devices that have been updated successfully:
• UEFI dbx (20250507 → 20250902)
• UEFI CA (2011 → 2023)
Uploading firmware reports helps hardware vendors to quickly identify failing and successful updates on real devices.
Review and upload report now? (Requires internet connection) \[Y|n\]: Y
Target:                  https://fwupd.org/lvfs/firmware/report
Payload:                 {
“ReportType” : “history”,
“ReportVersion” : 2,
“MachineId” : “d023f165dd3cbce72d95de0759d16dbfd31b3bb064f0acf769bb77a49b544e8b”,
“Metadata” : {
“CompileVersion(info.libusb)” : “1.0.27”,
“HostBiosMinorRelease” : “16”,
“HostFirmwareMinorRelease” : “16”,
“DisplayState” : “connected”,
“DistroId” : “ubuntu”,
“HostBaseboardProduct” : “LNVNB161216”,
“CompileVersion(com.hughsie.libxmlb)” : “0.3.24”,
“CompileVersion(com.hughsie.libjcat)” : “0.2.3”,
“EfivarsNvramUsed” : “66750”,
“HostBiosVendor” : “LENOVO”,
“PlatformArchitecture” : “x86_64”,
“HostBiosMajorRelease” : “01”,
“CompileVersion(org.freedesktop.fwupd)” : “2.0.20”,
“HostBaseboardManufacturer” : “LENOVO”,
“EfivarsNvramFree” : “72230”,
“CpuModel” : “Intel 13th Gen Intel Core™ i5-13420H”,
“KernelName” : “Linux”,
“BootTime” : “1782058200”,
“HostProduct” : “83A1”,
“HostFirmwareMajorRelease” : “01”,
“RuntimeVersion(org.freedesktop.fwupd-efi)” : “1.4”,
“BatteryThreshold” : “25”,
“RuntimeVersion(com.hughsie.libxmlb)” : “0.3.24”,
“LidState” : “open”,
“DistroName” : “Ubuntu”,
“RuntimeVersion(com.hughsie.libjcat)” : “0.2.3”,
“FwupdSupported” : “True”,
“DistroPrettyName” : “Ubuntu 24.04.4 LTS”,
“PowerState” : “ac”,
“KernelVersion” : “6.17.0-35-generic”,
“HostVendor” : “LENOVO”,
“HostBiosVersion” : “MCCN22WW”,
“HostFamily” : “V15 G4 IRU”,
“BatteryLevel” : “97”,
“CpuArchitecture” : “x86_64”,
“RuntimeVersion(org.kernel)” : “6.17.0-35-generic”,
“RuntimeVersion(org.freedesktop.fwupd)” : “2.0.20”,
“DistroVersion” : “24.04”,
“HostSku” : “LENOVO_MT_83A1_BU_idea_FM_V15 G4 IRU”,
“HostEnclosureKind” : “a”
},
“Reports” : \[
{
“Checksum” : “7178302fa23fcb875e7540900e299fb30a76758663efb7e1c56edc25cd3f316a”,
“ReleaseId” : “130035”,
“Protocol” : “org.uefi.dbx2”,
“UpdateState” : 2,
“Guid” : \[
“f8ba2887-9411-5c36-9cee-88995bb39731”
\],
“Plugin” : “uefi_dbx”,
“VersionOld” : “20250507”,
“VersionNew” : “20250902”,
“Flags” : 4653133749813539,
“Created” : 1781978411,
“Modified” : 1781985495,
“Metadata” : {
“CompileVersion(info.libusb)” : “1.0.27”,
“HostBiosMinorRelease” : “16”,
“HostFirmwareMinorRelease” : “16”,
“CompileVersion(org.freedesktop.fwupd)” : “2.0.20”,
“DistroId” : “ubuntu”,
“HostBaseboardProduct” : “LNVNB161216”,
“CompileVersion(com.hughsie.libxmlb)” : “0.3.24”,
“CompileVersion(com.hughsie.libjcat)” : “0.2.3”,
“EfivarsNvramUsed” : “63387”,
“HostBiosVendor” : “LENOVO”,
“HostBiosMajorRelease” : “01”,
“PlatformArchitecture” : “x86_64”,
“DisplayState” : “connected”,
“BootloaderSupportsFwupd” : “False”,
“EfivarsNvramFree” : “110291”,
“CpuModel” : “Intel 13th Gen Intel Core™ i5-13420H”,
“KernelName” : “Linux”,
“BatteryThreshold” : “25”,
“HostProduct” : “83A1”,
“HostFirmwareMajorRelease” : “01”,
“BootTime” : “1781978039”,
“RuntimeVersion(org.freedesktop.fwupd-efi)” : “1.4”,
“KernelVersion” : “6.17.0-35-generic”,
“RuntimeVersion(com.hughsie.libxmlb)” : “0.3.24”,
“LidState” : “open”,
“DistroName” : “Ubuntu”,
“RuntimeVersion(com.hughsie.libjcat)” : “0.2.3”,
“UefiPkKeyId” : “ae3bb84d4581781587a40e4315b48df56938ff6c”,
“FwupdSupported” : “True”,
“DistroPrettyName” : “Ubuntu 24.04.4 LTS”,
“PowerState” : “ac”,
“HostVendor” : “LENOVO”,
“HostBiosVersion” : “MCCN22WW”,
“HostFamily” : “V15 G4 IRU”,
“BatteryLevel” : “97”,
“SecureBoot” : “Disabled”,
“CpuArchitecture” : “x86_64”,
“UEFIUXCapsule” : “Enabled”,
“BootMgrDesc” : “legacy”,
“RuntimeVersion(org.kernel)” : “6.17.0-35-generic”,
“RuntimeVersion(org.freedesktop.fwupd)” : “2.0.20”,
“DistroVersion” : “24.04”,
“HostBaseboardManufacturer” : “LENOVO”,
“HostSku” : “LENOVO_MT_83A1_BU_idea_FM_V15 G4 IRU”,
“HostEnclosureKind” : “a”
}
},
{
“Checksum” : “4bdf420ad7e5ddde89d7a66ffe1b4328927059d56551f03afac855c4ed80f6c3”,
“ReleaseId” : “116503”,
“Protocol” : “org.uefi.dbx2”,
“UpdateState” : 2,
“Guid” : \[
“26f42cba-9bf6-5365-802b-e250eb757e96”
\],
“Plugin” : “uefi_db”,
“VersionOld” : “2011”,
“VersionNew” : “2023”,
“Flags” : 4644337119920419,
“Created” : 1782040945,
“Modified” : 1782058179,
“Metadata” : {
“CompileVersion(info.libusb)” : “1.0.27”,
“HostBiosMinorRelease” : “16”,
“HostFirmwareMinorRelease” : “16”,
“CompileVersion(org.freedesktop.fwupd)” : “2.0.20”,
“DistroId” : “ubuntu”,
“HostBaseboardProduct” : “LNVNB161216”,
“CompileVersion(com.hughsie.libxmlb)” : “0.3.24”,
“CompileVersion(com.hughsie.libjcat)” : “0.2.3”,
“EfivarsNvramUsed” : “63435”,
“HostBiosVendor” : “LENOVO”,
“PlatformArchitecture” : “x86_64”,
“HostBiosMajorRelease” : “01”,
“DisplayState” : “connected”,
“HostBaseboardManufacturer” : “LENOVO”,
“EfivarsNvramFree” : “84403”,
“RuntimeVersion(org.freedesktop.fwupd-efi)” : “1.4”,
“KernelName” : “Linux”,
“BatteryThreshold” : “25”,
“HostProduct” : “83A1”,
“HostFirmwareMajorRelease” : “01”,
“BootTime” : “1782039980”,
“CpuModel” : “Intel 13th Gen Intel Core™ i5-13420H”,
“KernelVersion” : “6.17.0-35-generic”,
“FwupdSupported” : “True”,
“LidState” : “open”,
“RuntimeVersion(com.hughsie.libxmlb)” : “0.3.24”,
“DistroName” : “Ubuntu”,
“UefiPkKeyId” : “ae3bb84d4581781587a40e4315b48df56938ff6c”,
“BatteryLevel” : “97”,
“DistroPrettyName” : “Ubuntu 24.04.4 LTS”,
“PowerState” : “ac”,
“HostVendor” : “LENOVO”,
“HostBiosVersion” : “MCCN22WW”,
“HostFamily” : “V15 G4 IRU”,
“CpuArchitecture” : “x86_64”,
“RuntimeVersion(com.hughsie.libjcat)” : “0.2.3”,
“RuntimeVersion(org.kernel)” : “6.17.0-35-generic”,
“RuntimeVersion(org.freedesktop.fwupd)” : “2.0.20”,
“DistroVersion” : “24.04”,
“HostSku” : “LENOVO_MT_83A1_BU_idea_FM_V15 G4 IRU”,
“HostEnclosureKind” : “a”
}
}
\]
}
Proceed with upload? \[Y|n\]: n
User declined action

Are those actually the same; could follow-ups. There was also some revocation of something called the IGEL boot loader, IIRC.

No need to wait.

The actual command action isn’t all that complicated.

That’s purely optional and only comes after the command has done it’s thing. The verbosity of the report is kind of the point. I cannot see any personally identifiable info in there, so nobody is spying on you, as a person; they only care about the specs of your machine. Think of it as helping to ensure that it is indeed safe to run that tool.


BTW, I meant to also link this topic but couldn’t find it yesterday; thankfully it just got bumped:

1 Like

I did not wait for long, the last notification appeared soon, so I was able to do the remaining update (KEK CA). The procedure was smooth and fast and required a restart after each of the three updates. Probably running fwupdmgr from terminal would be quicker, but this time I did not need it. Thanks for your help.

1 Like

I understand, but for next time, don’t worry. It’s simply listing everything that might be supported (not updated, merely potentially supported at some time). Mine is also verbose. Use those three commands any time you wish to manually update.

Lenovo is a reputable company, and its firmware updates are likely to improve your computer, and highly unlikely to cause a problem (though never say “never”).

3 Likes